diff --git a/Web/t/01_endpoints/01_admin/07_invites.t b/Web/t/01_endpoints/01_admin/07_invites.t new file mode 100644 index 0000000..70a73be --- /dev/null +++ b/Web/t/01_endpoints/01_admin/07_invites.t @@ -0,0 +1,52 @@ +#!/usr/bin/env perl +use MJB::Web::Test; + +#== +# This test file ensures that invite codes panel can be seen by admins, but not +# normal users or anonymouse users. +#== + +my $t = Test::Mojo::MJB->new('MJB::Web'); + +# Make sure an unauthed user cannot access this. +$t->get_ok( '/admin/invites' ) + ->status_is( 302 ) + ->header_is( location => '/login', 'Anonymouse users may not access the admin invites panel.' ); + +# Register a user account and log into it. +# +# A normal user should still not be allowed to view this page. +# +# Promote the user to an admin +$t->app->config->{register}{enable_open} = 1; +$t->post_ok( '/register/open', form => { + name => 'fred', + email => 'fred@blog.com', + password => 'SuperSecure', + password_confirm => 'SuperSecure', + }) + ->status_is( 302 ) + ->code_block( sub { + is( scalar(@{shift->stash->{errors}}), 0, 'No errors' ); + }) + ->get_ok( '/admin/invites' ) + ->status_is( 302 ) + ->header_is( location => '/dashboard', 'Normal users may not access the admin invites panel.' ) + ->get_ok( '/' ) + ->code_block( sub { + my $self = shift; + $self->stash->{person}->is_admin( 1 ); + ok( $self->stash->{person}->update, 'Promoted fred to an admin' ); + }); + +# Check to ensure that the invite code array exists. +$t->get_ok( '/admin/invites' ) + ->status_is( 200 ) + ->code_block( sub { + my $self = shift; + + is ref($self->stash->{invites}), 'ARRAY', 'Have an array ref for invite codes.'; + is scalar(@{$self->stash->{invites}}), 0, 'No entries for invite codes currently.'; + }); + +done_testing; diff --git a/Web/t/01_endpoints/01_admin/08_do_invite.t b/Web/t/01_endpoints/01_admin/08_do_invite.t new file mode 100644 index 0000000..883b124 --- /dev/null +++ b/Web/t/01_endpoints/01_admin/08_do_invite.t @@ -0,0 +1,61 @@ +#!/usr/bin/env perl +use MJB::Web::Test; + +#== +# This test file ensures that invite codes can be added through the admin panel. +# +# It creates an admin user, who then creates an invite code, and it confirms the +# invite code exists in the stash for the /admin/invites page. +#== + +my $t = Test::Mojo::MJB->new('MJB::Web'); + +# Make sure an unauthed user cannot access this. +$t->get_ok( '/admin/invites' ) + ->status_is( 302 ) + ->header_is( location => '/login', 'Anonymouse users may not access the admin invites panel.' ); + +# Register a user account and log into it. +# +# A normal user should still not be allowed to view this page. +# +# Promote the user to an admin +$t->app->config->{register}{enable_open} = 1; +$t->post_ok( '/register/open', form => { + name => 'fred', + email => 'fred@blog.com', + password => 'SuperSecure', + password_confirm => 'SuperSecure', + }) + ->status_is( 302 ) + ->code_block( sub { + is( scalar(@{shift->stash->{errors}}), 0, 'No errors' ); + }) + ->get_ok( '/admin/invites' ) + ->status_is( 302 ) + ->header_is( location => '/dashboard', 'Normal users may not access the admin invites panel.' ) + ->get_ok( '/' ) + ->code_block( sub { + my $self = shift; + $self->stash->{person}->is_admin( 1 ); + ok( $self->stash->{person}->update, 'Promoted fred to an admin' ); + }); + +# Add an invite code. +$t->post_ok( '/admin/invite', form => { + code => 'my-code', + is_multi_use => 0, + }) + ->header_is( location => '/admin/invites' ); + +# Check to ensure that the invite code exists now. +$t->get_ok( '/admin/invites' ) + ->status_is( 200 ) + ->code_block( sub { + my $self = shift; + + is ref($self->stash->{invites}), 'ARRAY', 'Have an array ref for invite codes.'; + is $self->stash->{invites}->[0]->code, 'my-code', 'Have an entry for the invite code.'; + }); + +done_testing; diff --git a/Web/t/01_endpoints/01_admin/09_do_invite_remove.t b/Web/t/01_endpoints/01_admin/09_do_invite_remove.t new file mode 100644 index 0000000..791c596 --- /dev/null +++ b/Web/t/01_endpoints/01_admin/09_do_invite_remove.t @@ -0,0 +1,74 @@ +#!/usr/bin/env perl +use MJB::Web::Test; + +#== +# This test file ensures that invite codes can be removed through the admin panel. +# +# It creates an admin user, who then creates an invite code, and it confirms the +# invite code exists in the stash for the /admin/invites page, then it deletes the +# invite and confirms it is no longer available. +#== + +my $t = Test::Mojo::MJB->new('MJB::Web'); + +# Make sure an unauthed user cannot access this. +$t->get_ok( '/admin/invites' ) + ->status_is( 302 ) + ->header_is( location => '/login', 'Anonymouse users may not access the admin invites panel.' ); + +# Register a user account and log into it. +# +# A normal user should still not be allowed to view this page. +# +# Promote the user to an admin +$t->app->config->{register}{enable_open} = 1; +$t->post_ok( '/register/open', form => { + name => 'fred', + email => 'fred@blog.com', + password => 'SuperSecure', + password_confirm => 'SuperSecure', + }) + ->status_is( 302 ) + ->code_block( sub { + is( scalar(@{shift->stash->{errors}}), 0, 'No errors' ); + }) + ->get_ok( '/admin/invites' ) + ->status_is( 302 ) + ->header_is( location => '/dashboard', 'Normal users may not access the admin invites panel.' ) + ->get_ok( '/' ) + ->code_block( sub { + my $self = shift; + $self->stash->{person}->is_admin( 1 ); + ok( $self->stash->{person}->update, 'Promoted fred to an admin' ); + }); + +# Add an invite code. +$t->post_ok( '/admin/invite', form => { + code => 'my-code', + is_multi_use => 0, + }) + ->header_is( location => '/admin/invites' ); + +# Check to ensure that the invite code exists now, and remove it. +$t->get_ok( '/admin/invites' ) + ->code_block( sub { + my $self = shift; + + is ref($self->stash->{invites}), 'ARRAY', 'Have an array ref for invite codes.'; + is $self->stash->{invites}->[0]->code, 'my-code', 'Have an entry for the invite code.'; + + # Now we will remove the invite code. + $t->post_ok( '/admin/invite/remove', form => { iid => $self->stash->{invites}->[0]->id }) + ->header_is( location => '/admin/invites' ); + }); + +# Confirm the invite code has been removed. +$t->get_ok( '/admin/invites' ) + ->code_block( sub { + my $self = shift; + + is ref($self->stash->{invites}), 'ARRAY', 'Have an array ref for invite codes'; + is scalar(@{$self->stash->{invites}}), 0, 'Invite code was removed.'; + }); + +done_testing;